Romanian government's land registry agency
Incident posture
Linked entities
- Victim
- Romanian government's land registry agency
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A ransomware attack on the Romanian government's land registry agency wiped its entire database and caused major disruption to the nation's real estate market. The incident was cited as one of the significant ransomware events in an analysis that noted a 19% rise in attacks compared to the previous month. Analysts highlighted the attack for demonstrating how ransomware groups can delete large datasets, underscoring the importance of reliable backups for recovery.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In July 2026, Comparitech recorded 799 claimed ransomware attacks, marking a 19% increase from June and the second highest month of the year. The analysis, published on August 5, 2026, highlighted several major confirmed incidents, including one affecting the Romanian government's land registry agency. The incident occurred during the broader surge in ransomware activity that saw finance, technology, healthcare, and education sectors experience notable month‑by‑month increases. The land registry agency attack was identified as a ransomware event that led to the wiping of its entire database. This event was noted alongside other significant incidents such as the attack on US healthcare provider AnMad.
The wiping of the land registry agency's database caused significant disruption to Romania's real estate market, as property transactions and records became inaccessible. No further details about the attack vector, ransom demand, or threat actor attribution are provided in the source material. The source does not describe any detection, containment, or remediation actions taken by the agency or authorities. Consequently, the narrative is limited to the confirmed outcome of data loss and the resulting market disruption. The incident remains cited as an example of ransomware groups deleting massive datasets to inflict operational harm.
Sources
Sources available to members: 1 source.